CHFI OS and Network Forensics Practice Question
During a Linux forensic investigation, you find that the /var/log/auth.log file contains log entries showing multiple 'Failed password for root' messages from a single IP address, followed by a 'Accepted password for root' entry. What is the MOST likely conclusion?
⚠ Common exam trap
EC-Council CHFI often tests the distinction between authentication log patterns and exploit-based compromise, so the trap here is assuming that any successful login after failures must be a privilege escalation, when the log entries explicitly show password-based authentication succeeded.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An attacker successfully brute-forced the root password
The sequence of multiple 'Failed password for root' entries followed by an 'Accepted password for root' entry from the same IP address is the classic signature of a successful brute-force attack against the root account. SSH authentication logs record each attempt, and a successful login after repeated failures indicates that the attacker guessed or cracked the password, not that a privilege escalation or lockout occurred.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An attacker successfully brute-forced the root password
Why this is correct
Repeated 'Failed password for root' entries from one source, immediately followed by 'Accepted password for root', indicate sustained password guessing that eventually succeeded. The single IP and root-targeted pattern distinguish brute force from a legitimate login or configuration error.
- ✗
The root user accidentally mistyped the password multiple times
Why it's wrong here
Repeated failures from a single remote IP address followed by acceptance indicates deliberate password guessing, not a local user mistyping at a console. Mistyped-password patterns appear as failures from the same trusted workstation or terminal, typically without a remote source address.
- ✗
The system was compromised via a privilege escalation exploit
Why it's wrong here
Repeated failures from one IP followed by an accepted root login indicates a successful brute-force or password-guessing attack, not exploitation of a local privilege escalation flaw. Privilege escalation analysis applies when a low-privileged account gains root through a kernel or SUID vulnerability after authenticating normally.
- ✗
The root account has been locked out due to multiple failures
Why it's wrong here
The log shows an accepted password after the failures, so the account was not locked; lockout would appear as further denials or a locked-account message. Lockout analysis is the right conclusion when failures continue past the configured threshold without any subsequent successful authentication.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.